# CAPTCHA

2Captcha is the only launch provider. The user supplies and funds the key through an encrypted saved connector or a request-scoped key. CAPTCHA solving requires `mode: on_challenge`, defaults to one task, and requires the `captcha:use` scope, current entitlement, and an available isolated execution lane. Keys and solver identifiers are secrets and never enter telemetry, remote worker RPC, Firecracker guests, or public output. The renderer fails closed while the opaque host callback or paid-provider launch check is unavailable.
